[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Malware](https://unit42.paloaltonetworks.com/category/malware/ "Malware")  
  [Malware](https://unit42.paloaltonetworks.com/category/malware/)

# Threat Actors Target Government of Belarus Using CMSTAR Trojan

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 12 min read  
Related Products  
[![Advanced WildFire icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/strata_RGB_logo_Icon_Color.png)Advanced WildFire](https://unit42.paloaltonetworks.com/product-category/advanced-wildfire/ "Advanced WildFire")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:September 28, 2017

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Malware](https://unit42.paloaltonetworks.com/category/malware/)
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [BYEBY](https://unit42.paloaltonetworks.com/tag/byeby/)
  * [Cmstar](https://unit42.paloaltonetworks.com/tag/cmstar/)
  * [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/)
  * [PYLOT](https://unit42.paloaltonetworks.com/tag/pylot/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/unit42-threat-actors-target-government-belarus-using-cmstar-trojan/?pdf=download&lg=en&_wpnonce=46edad538b "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/unit42-threat-actors-target-government-belarus-using-cmstar-trojan/?pdf=print&lg=en&_wpnonce=46edad538b "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Threat%20Actors%20Target%20Government%20of%20Belarus%20Using%20CMSTAR%20Trojan&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-threat-actors-target-government-belarus-using-cmstar-trojan%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-threat-actors-target-government-belarus-using-cmstar-trojan%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-threat-actors-target-government-belarus-using-cmstar-trojan%2F&title=Threat%20Actors%20Target%20Government%20of%20Belarus%20Using%20CMSTAR%20Trojan "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-threat-actors-target-government-belarus-using-cmstar-trojan%2F&text=Threat%20Actors%20Target%20Government%20of%20Belarus%20Using%20CMSTAR%20Trojan "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-threat-actors-target-government-belarus-using-cmstar-trojan%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Threat%20Actors%20Target%20Government%20of%20Belarus%20Using%20CMSTAR%20Trojan%20https%3A%2F%2Funit42.paloaltonetworks.com%2Funit42-threat-actors-target-government-belarus-using-cmstar-trojan%2F "Share in Mastodon")
  Palo Alto Networks Unit 42 has identified a series of phishing emails containing updated versions of the previously discussed [CMSTAR malware family](https://blog.paloaltonetworks.com/tag/cmstar/) targeting various government entities in the country of Belarus.

We first reported on CMSTAR in [spear phishing attacks in spring of 2015](https://blog.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/) and later [in 2016](https://blog.paloaltonetworks.com/2016/03/digital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government/).

In this latest campaign, we observed a total of 20 unique emails between June and August of this year that included two new variants of the CMSTAR Downloader. We also discovered two previously unknown payloads. These payloads contained backdoors that we have named BYEBY and PYLOT respectively.

![CMSTAR\_1](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_1.png)

*Figure 1 Diagram of the attack sequence*

## **Phishing Emails**

Between June and August of this year, we observed a total of 20 unique emails being sent to the following email addresses:

|-------------------------------|-------------------------------------------------------------------------------------|
| **Email Address**             | **Description**                                                                     |
| press@mod.mil\[.\]by          | Press Service of the Ministry of Defense of the Republic of Belarus                 |
| baranovichi\_eu@mod.mil\[.\]by | Baranovichi Operational Management of the Armed Forces                              |
| modmail@mod.mil\[.\]by        | Ministry of Defense of the Republic of Belarus                                      |
| admin@mod.mil\[.\]by          | Ministry of Defense of the Republic of Belarus                                      |
| itsc@mod.mil\[.\]by           | Unknown. Likely used by Ministry of Defense of the Republic of Belarus              |
| mineuvs@mod.mil\[.\]by        | Minsk Operational Administration of the Armed Forces                                |
| inform@mod.mil\[.\]by         | Unknown. Likely used by Ministry of Defense of the Republic of Belarus              |
| uporov\_milcoop@mod.mil\[.\]by | Unknown. Likely used by Ministry of Defense of the Republic of Belarus              |
| video@gpk.gov\[.\]by          | State Border Committee of the Republic of Belarus                                   |
| armscontrol@mfa.gov\[.\]by    | International Security and Arms Control Department, Ministry of Foreign Affairs     |
| ablameiko@mia\[.\]by          | Unknown. Likely used by the Ministry of Internal Affairs of the Republic of Belarus |

These emails contained a series of subject lines, primarily revolving around the topic of Запад-2017 (['West-2017'](https://ru.wikipedia.org/wiki/%D0%97%D0%B0%D0%BF%D0%B0%D0%B4-2017)), also known in English as [Zapad 2017](https://en.wikipedia.org/wiki/Zapad_2017_exercise). Zapad 2017 was a series of joint military exercises conducted by the Armed Forces of the Russian Federation and the Republic of Belarus, held from September 14th to 20th in 2017.

The full list of subject lines is as follows:

* Fwd:Подготовка к Запад-2017 \[Translation: Fwd:Preparing for the West-2017\]
* выпуск воспитанников \[Translation: graduation\]
* К Запад-2017 \[Translation: To West-2017\]
* Запад-2017 \[Translation: West-2017\]

An example of some of the previously mentioned emails may be seen below.

![CMSTAR\_2](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_2.png)

*Figure 2 Phishing email sent to Belarus government (1/2)*

![CMSTAR\_3](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_3.png)

*Figure 3 Phishing email sent to Belarus government (2/2)*

## **Decoy Documents**

We observed that the attachments used in these emails contained a mixture of file types. RTF documents, Microsoft Word documents, and a RAR archive. The RAR archive contained a series of images, a decoy document, and a Microsoft Windows executable within it. The executable has a .scr file extension, and is designed to look like a Windows folder, as seen below:

![CMSTAR\_4](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_4.png)

*Figure 4 Payload disguising itself as a Microsoft Windows folder*

The rough translation of the folder and file names above are 'Preparations for large-scale West-2017 exercises in this format are being held for the first time.' Within the actual folder, there are a series of JPG images, as well as a decoy document with a title that is translated to 'Thousands of Russian and Belarusian military are involved in the training of the rear services.'

![CMSTAR\_5](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_5.png)

*Figure 5 Embedded images and decoy document within RAR*

The decoy document contains the following content:

![CMSTAR\_6](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_6.png)

*Figure 6 Decoy document within RAR*

The other RTF and Word documents used additional decoy documents, which can be seen below.

![CMSTAR\_7](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_7.png)

*Figure 7 Decoy document with translation (1/2)*

![CMSTAR\_8](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_8.png)

*Figure 8 Decoy document with translation (2/2)*

While we observed different techniques being used for delivery, all attachments executed a variant of the CMSTAR malware family. We observed minor changes between variants, which we discuss in the CMSTAR Variations and Payloads section of the blog post.

The Word documents, which we track as Werow, employ malicious macros for their delivery. More information about these macros may be found in the [Appendix](#Appendix) of the blog post. Additionally, we have included a script that extracts these embedded payloads that can also be found in the Appendix.

The RTF documents made use of [CVE-2015-1641](https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-1641). This vulnerability, patched in 2015, allows attackers to execute malicious code when these specially crafted documents are opened within vulnerable instances of Microsoft Word. The payload for these samples is embedded within them and obfuscated using a 4-byte XOR key of 0xCAFEBABE. We have included a script that can be used to extract the underlying payload of these RTFs statically that can be found in the Appendix.

The SCR file mentioned previously drops a CMSTAR DLL and runs it via an external call to rundll32.exe.

## **CMSTAR Variations and Payloads**

In total, we observed three variations of CMSTAR in these recent attacks against Belarusian targets. The biggest change observed between them looks to be minor modifications made to the string obfuscation routine. A very simple modification to the digit used in subtraction was modified between the variants, as shown below:

![CMSTAR\_9](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_9.png)

*Figure 9 String obfuscation modifications between CMSTAR variants*

The older variation, named CMSTAR.A, was discussed in a previous blog post entitled, "[Digital Quartermaster Scenario Demonstrated in Attacks Against the Mongolian Government](https://blog.paloaltonetworks.com/2016/03/digital-quartermaster-scenario-demonstrated-in-attacks-against-the-mongolian-government/)."

The CMSTAR.B variant was witnessed using both a different mutex from CMSTAR.A, as well as a slightly modified string obfuscation routine. The mutexes used by CMSTAR ensure that only one instance of the malware runs at a time. The CMSTAR.C variant used the same mutex as CMSTAR.B, however, again used another slightly modified string obfuscation routine. We found all CMSTAR variants using the same obfuscation routine when I payload was downloaded from a remote server. We have included a tool to extract mutex and C2 information from all three CMSTAR variants, as well as a tool to decode the downloaded payload: both may be found in the Scripts section.

An example of CMSTAR downloading its payload may be found below:

![CMSTAR\_10](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_10.png)

*Figure 10 Example HTTP download by CMSTAR*

When expanding the research to identify additional CMSTAR.B and CMSTAR.C variants, we identified a total of 31 samples. Of these 31 samples, we found two unique payloads served from three of the C2 URLS---One of which was downloaded from a sample found in the phishing attacks previously described. Both payloads contained previously unknown malware families. We have named the payload found in the email campaign PYLOT, and the malware downloaded from the additional CMSTAR samples BYEBY.

Both malware families acted as backdoors, allowing the attackers to execute commands on the victim machine, as well as a series of other functions. More information about these individual malware families may be found in the appendix.

## **Conclusion**

During the course of this research, we identified a phishing campaign consisting of 20 unique emails targeting the government of Belarus. The ploys used in these email and decoy documents revolved around a joint strategic military exercise of the Armed Forces of the Russian Federation and the Republic of Belarus, which took place between September 14^th^ and September 20^th^ of this year. While looking at the emails in question, we observed two new variants of the CMSTAR malware family. Between the samples identified and others we found while expanding our research scope, we identified two previously unknown malware families.

Palo Alto customers are protected from this threat in the following ways:

* Tags have been created in AutoFocus to track [CMSTAR](https://autofocus.paloaltonetworks.com/#/tag/Unit42.Cmstar), [BYEBY](https://autofocus.paloaltonetworks.com/#/tag/Unit42.BYEBY), and [PYLOT](https://autofocus.paloaltonetworks.com/#/tag/Unit42.PYLOT)
* All observed samples are identified as malicious in WildFire
* Domains observed to act as C2s have been flagged as malicious
* Traps 4.1 identifies and blocks the CVE-2015-1641 exploit used in these documents
* Traps 4.1 blocks the macros used in the malicious Word documents

A special thanks to Tom Lancaster for his assistance on this research.

## **Appendix**

### **Werow Macro Analysis**

The attacker used the same macro dropper all of the observed Microsoft Word documents we analyzed for this campaign. It begins by building the following path strings:

* %APPDATA%\\d.doc
* %APPDATA%\\Microsoft\\Office\\WinCred.acl

The 'd.doc' path will be used to store a copy of the Word document, while the 'WinCred.acl' will contain the dropped payload, which is expected to be a DLL.

![CMSTAR\_11](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_11.png)

*Figure 11 Macro used to drop CMSTAR*

Werow uses rudimentary obfuscation to hide and re-assemble the following strings:

* HKCU\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WinCred
* rundll32 %APPDATA%\\Microsof\\Office\\WinCred.acl ,WinCred

These strings will be used at the end of the macro's execution to ensure persistence via the Run registry key.

The malware proceeds to read an included overlay within the original Word document from a given offset. This data is decoded using and XOR operation, as well as an addition operation. It can be represented in Python as follows:  
def decrypt\_xor(data, key, key\_offset): output = "" seed = ord(key) for d in data: ord\_d = ord(d) if ord\_d != 0 and ord\_d != seed: nvalue = ord\_d ^ seed seed = (seed + key\_offset) % 0x100 output += chr(nvalue) else: output += d return output

|----------------------------|----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 | def decrypt\_xor(data, key, key\_offset): output = "" seed = ord(key) for d in data: ord\_d = ord(d) if ord\_d != 0 and ord\_d != seed: nvalue = ord\_d ^ seed seed = (seed + key\_offset) % 0x100 output += chr(nvalue) else: output += d return output |

Once this overlay is decoded, it is written to the 'WinCred.acl' file and loaded with the 'WinCred' export. A script has been provided in the Scripts section that, in conjunction with oletools, can statically extract the embedded DLL payload from these documents.

### **RTF Shellcode Analysis**

The RTF documents delivered in this attack campaign appear to be created by the same builder. All of the RTF files attempt to exploit CVE-2015-1641 to execute shellcode on the targeted system. Please reference https://technet.microsoft.com/en-us/library/security/ms15-033.aspx for more information.

The shellcode executed after successful exploitation begins by resolving the API functions it requires by enumerating the API functions within loaded modules in the current process. It then builds the following list of values:

![CMSTAR\_12](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_12.png)

The shellcode then enumerates the API functions, subjects them to a ROR7 hashing routine and XORs the resulting hash with 0x10ADBEEF. It uses the result of this arithmetic to compare with the list of values above to find the API functions it requires to carry out its functionality.

|----------|----------------------|-------------------------|
| **ROR7** | **ROR7^0x10ADBEEF** | **API Func**            |
| 1a22f51  | 110f91be             | WinExec                 |
| 741f8dc4 | 64b2332b             | WriteFile               |
| 94e43293 | 84498c7c             | CreateFileA             |
| daa7fe52 | ca0a40bd             | UnmapViewOfFile         |
| dbacbe43 | cb0100ac             | SetFilePointer          |
| ec496a9e | fce4d471             | GetEnvironmentVariableA |
| ff0d6657 | efa0d8b8             | CloseHandle             |

After resolving the API functions, the shellcode then begins searching for the embedded payload and decoy within the initial RTF file. It does so by searching the RTF file for three delimiters, specifically 0xBABABABABABA, 0xBBBBBBBB and 0xBCBCBCBC, which the shellcode uses to find the encrypted payload and decoy. The shellcode then decrypts the payload by XOR'ing four bytes at at time with the key 0xCAFEBABE, and decrypts the decoy by XOR'ing four bytes at a time using the key 0xBAADF00D. Here is a visual representation of the delimiters and embedded files:

![CMSTAR\_delimiters](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/screenshot-4-1.png)

After decrypting the payload, it saves the file to the following location:

%APPDATA%\\Microsoft\\Office\\OutL12.pip

The shellcode then creates the following registry key to automatically run the payload each time the system starts:

Software\\Microsoft\\Windows\\CurrentVersion\\Run : Microsoft

The shellcode saves the following command to this autorun key, which will execute the OutL12.pip payload, specifically calling its 'WinCred' exported function:

rundll32.exe  
"%APPDATA\\Roaming\\Microsoft\\Office\\OutL12.pip",WinCred

The shellcode will then overwrite the original delivery document with the decrypted decoy contents and open the new document.

### **PYLOT Analysis**

This malware family was named via a combination of the DLLs original name of 'pilot.dll', along with the fact it downloads files with a Python (.py) file extension.

PYLOT begins by being loaded as a DLL with the ServiceMain export. It proceeds to create the following two folders within the %TEMP% path:

* KB287640
* KB887209

PYLOT continues to load and decode an embedded resource file. This file contains configuration information that is used by the malware throughout its execution. The following script, written in Python, may be used to decode this embedded resource object:  
import sys import hexdump file = sys.argv\[1\] fh = open(file, 'rb') fdata = list(fh.read()) fh.close() fdata\_len = len(fdata) c = fdata\_len-1 output = "" while c \&gt; 1: fdata\[c\] = chr( ord(fdata\[c\]) ^ ord(fdata\[c-2\]) ) c -= 1 fdata = ''.join(fdata) hexdump.hexdump(fdata)

|----------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 | import sys import hexdump file = sys.argv\[1\] fh = open(file, 'rb') fdata = list(fh.read()) fh.close() fdata\_len = len(fdata) c = fdata\_len-1 output = "" while c \&gt; 1: fdata\[c\] = chr( ord(fdata\[c\]) ^ ord(fdata\[c-2\]) ) c -= 1 fdata = ''.join(fdata) hexdump.hexdump(fdata) |

Looking at the decoded data, we see the following:

![CMSTAR\_13](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_13.png)

*Figure 12 Decoded embedded configuration information*

The malware continues to collect the following information from the victim computer:

* Computer name
* IP addresses present on the machine
* MAC addresses
* Microsoft Windows version information
* Windows code page identifier information

This information is used to generate a unique hash for the victim machine. PYLOT then begins entering its C2 handler routine, where it will use HTTP for communication with the remote host.

Data sent to the remote C2 server is encrypted using RC4 with the previously shown key of 'BBidRotnqQpHfpRTi8cR.' It is then further obfuscated by base64-encoding this encrypted string. An example of this HTTP request containing this data can be seen below.

![CMSTAR\_14](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_14-1.png)

*Figure 13 HTTP request made by PYLOT to remote server*

The decrypted data sent in the request above is as follows. Note that all of this custom data format has not been fully identified, however, we're able to see various strings, including the embedded configuration string of 'fGAka0001', as well as the victim hash of '100048048.'

![CMSTAR\_15](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_15.png)

*Figure 14 Decrypted data sent by PYLOT to remote server*

The base64-encoded string at the end of the data contains the collected victim machine information from earlier, separated by a '|' delimiter.

The remote C2 server responds using the same data format. An example response can be seen below.

![CMSTAR\_16](https://unit42.paloaltonetworks.com/wp-content/uploads/2017/09/CMSTAR_16.png)

*Figure 15 Response from remote C2 server*

The decoded data at the end of the response contains various URIs to be used by the malware to receive commands, as well as other information that has yet to be fully researched.  
/duakzu/furs.py|/ugvrf/pvoi.py|/tydfw/pld.py|/bpnij/syau.py|/plugin/plugin.py|eycHhHKVQUnuAwtNchvYjScGYMtVMzMqYmxBmCEwieQpKgsokpvrxknPQRvnkOHDywCImVZxHxRdvlePjgnbPXsyTzreBEckVVFbuUHHcvLPGmqxHUNWondMIntBiVVO|CgpQxWOeTAbOLpOCdWtesymHSqjeSUYPQFBeUnbhXElorlcjqldwEMVucaDwJRhuzZjprKkZEPvLEWUbkEQxFUqzqIRQwyuTaBmOZSOpfJRByRvyTHjSVdVeihtkbcnG|GqPfDIAHOik/

|---|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|
| 1 | /duakzu/furs.py|/ugvrf/pvoi.py|/tydfw/pld.py|/bpnij/syau.py|/plugin/plugin.py|eycHhHKVQUnuAwtNchvYjScGYMtVMzMqYmxBmCEwieQpKgsokpvrxknPQRvnkOHDywCImVZxHxRdvlePjgnbPXsyTzreBEckVVFbuUHHcvLPGmqxHUNWondMIntBiVVO|CgpQxWOeTAbOLpOCdWtesymHSqjeSUYPQFBeUnbhXElorlcjqldwEMVucaDwJRhuzZjprKkZEPvLEWUbkEQxFUqzqIRQwyuTaBmOZSOpfJRByRvyTHjSVdVeihtkbcnG|GqPfDIAHOik/ |

A number of commands have been identified within PYLOT, including the following:  
• Download batch script  
• Run batch script  
• Delete file  
• Rename file  
• Execute file  
• Download file  
• Upload file

### **BYEBY Analysis**

BYEBY was named based on a string within the malware itself. Most strings found within this malware are concatenated to 6 characters. One such example was an instance where a debug string contained 'BYE BY', which was likely a concatenated form of the phrase 'BYE BYE'.

This malware is loaded as a DLL, with an export name of ServiceMain. When the malware is initially loaded, it begins by checking to see if it is running within either of the following paths:

* \[SYSTEM32\]\\svchost.exe
* \[SYSTEM32\]\\rundll32.exe

If it finds itself not running in either location, it will immediately exit. This is likely a technique used to bypass various sandboxing systems. Should it find itself running as svchost.exe, it will write the current timestamp and a value of 'V09SS010' (Base64 Decoded: 'WORKMN') to a file named 'vmunisvc.cab' within the user's local %TEMP% folder. This file acts as a lot file and is written to frequently throughout the malware's execution.

When the malware runs within the context of svchost.exe, it bypasses the installation routines and immediately enters the C2 handler.

When BYEBY is run within the context of rundll32.exe, it expects itself to be running for the first time. As such, it will register itself as a service with a name of 'VideoSrv.' After this service is created, BYEBY proceeds to enter it's C2 handler function in a new thread.

BYEBY uses TLS for network communication, connecting to the following host on port 443:

* oeiowidfla22\[.\]com

After the initial connection is established, BYEBY will collect the following system information and upload it to the remote C2:

* Hostname
* IP Address
* Embedded String of 'WinVideo'
* Major Windows Version
* Minor Windows Version
* Embedded String of '6.1.7603.16000'

The malware is configured to accept a number of commands. These appear to be Base64-encoded strings that, when decoded, provide their true meaning. Only the beginning of the commands are checked. The Base64-decoded strings have been included for the benefit of the reader.

* aGVsbG8h \[Decoded: hello!\]
* R09PREJZ \[Decoded: GOODBY\]
* TElTVCBE \[Decoded: LIST D\]
* U1RBUlRD \[Decoded: STARTC\]
* Q09NTUFO \[Decoded: COMMAN\]
* VFJBTlNG \[Decoded: TRANSF\]
* RVhFQ1VU \[Decoded: EXECUT\]

A mapping of commands and their descriptions has been provided:

|-------------|---------------------------------------------------|
| **Command** | **Description**                                   |
| aGVsbG8h    | Authenticate with the remote C2 server.           |
| R09PREJZ    | Close socket connection with remote server.       |
| TElTVCBE    | List drives on the victim machine.                |
| U1RBUlRD    | Start an interactive shell on the victim machine. |
| Q09NTUFO    | Execute a command in the interactive shell        |
| VFJBTlNG    | Upload or download files to the victim machine.   |
| RVhFQ1VU    | Execute command in a new process.                 |

### **Scripts**

We created multiple scripts during the course of our research. We are sharing them here to assist other researchers or defenders that encounter this malware.

[extract\_cmstar\_doc.py](https://github.com/pan-unit42/public_tools/blob/master/cmstar/extract_cmstar_doc.py) -- Script to extract the embedded CMSTAR payload from Word documents.

[extract\_cmstar\_rtf.py](https://github.com/pan-unit42/public_tools/blob/master/cmstar/extract_cmstar_rtf.py)-- Script to extract the embedded CMSTAR payload from RTFs.

[extract\_cmstar\_strings.py](https://github.com/pan-unit42/public_tools/blob/master/cmstar/extract_cmstar_strings.py) -- Script to identify possible mutex and C2 strings from CMSTAR variants.

[decode\_cmstar\_payload.py](https://github.com/pan-unit42/public_tools/blob/master/cmstar/decode_cmstar_payload.py) -- Script to decode a payload downloaded by CMSTAR.

## **Indicators of Compromise**

### **CMSTAR Variants Identified in Phishing Campaign**

65d5ef9aa617e7060779bc217a42372e99d59dc88f8ea2f3b9f45aacf3ba7209

2a0169c72c84e6d3fa49af701fd46ee7aaf1d1d9e107798d93a6ca8df5d25957

4da6ce5921b0dfff9045ada7e775c1755e6ea44eab55da7ccc362f2a70ce26a6

2008ec82cec0b62bdb4d2cea64ff5a159a4327a058dfd867f877536389a72fb6

cecd72851c265f885ff02c60cbc3e6cbf1a40b298274761f623dfa44782a01f8

d8c0f8ecdeceba83396c98370f8f458ea7f7a935aabbcc3d41b80d4e85746357

2c8267192b196bf8a92c8b72d52096e46e307fa4d4dafdc030d3e0f5b4145e9e

2debf12b1cb1291cbd096b24897856948734fa62fd61a1f24d379b4224bda212

79b30634075896084135b9891c42fca8a59db1c0c731e445940671efab9a0b61

b0065fc16ae785834908f024fb3ddd4d9d62b29675859a8e737e3b949e85327a

16697c95db5add6c1c23b2591b9d8eec5ed96074d057b9411f0b57a54af298d5

6843d183b41b6b22976fc8d85e448dcc4d2e0bd2c159e6d966bfd4afa1cd9221

3c3efa89d1dd39e1112558af38ba656e048be842a3bedb7933cdd4210025f791

b2bebb381bc3722304ab1a21a21e082583bf6b88b84e7f65c4fdda48971c20a2

09890dc8898b99647cdc1cceb97e764b6a88d55b5a520c8d0ea3bfd8f75ed83b

fd22973451b88a4d10d9f485baef7f5e7a6f2cb9ce0826953571bd8f5d866c2a

### **CMSTAR Download Locations in Phishing Campaign**

http://45.77.60\[.\]138/YXza9HkKWzqtXlt.dat  
http://45.77.60\[.\]138/mePVDjnAZsYCw5j.dat  
http://45.77.60\[.\]138/UScHrzGWbXb01gv.dat  
http://45.76.80\[.\]32/tYD7jzfVNZqMfye.dat  
http://45.77.60\[.\]138/liW0ecpxEWCfIgU.dat  
http://45.77.60\[.\]138/ezD19AweVIj5NaH.dat  
http://45.77.60\[.\]138/jVJlw3wp379neaJ.dat  
http://108.61.175\[.\]110/tlhXVFeBvT64LC9.dat  
http://45.77.60\[.\]138/HJDBvnJ7wc4S5qZ.dat  
http://45.77.60\[.\]138/JUmoT4Pbw6U2xcj.dat  
http://108.61.175\[.\]110/oiUfxZfej29MAbF.dat  
http://45.77.60\[.\]138/cw1PlY308OpfVeZ.dat  
http://45.77.60\[.\]138/VFdSKlgCAZD7mmp.dat  
http://45.77.60\[.\]138/c2KoCT5OHcVwGi7.dat  
http://45.77.60\[.\]138/3kK24dXFYRgM6Ac.dat  
http://45.77.60\[.\]138/WsEeRyHEhLO1kUm.dat

### **PYLOT SHA256**

7e2c9e4acd05bc8ca45263b196e80e919ff60890a872bdc0576735a566369c46

### **PYLOT C2**

wait.waisttoomuchmind\[.\]com

### **BYEBY SHA256**

383a2d8f421ad2f243cbc142e9715c78f867a114b037626c2097cb3e070f67d6

### **BYEBY C2**

oeiowidfla22\[.\]com

### **CMSTAR.B SHA256**

8609360b43498e296e14237d318c96c58dce3e91b7a1c608cd146496703a7fac

f0f2215457200bb3003eecb277bf7e3888d16edcf132d88203b27966407c7dc3

aecf53a3a52662b441703e56555d06c9d3c61bddf4d3b23d9da02abbe390c609

960a17797738dc0bc5623c74b6f8a5d74375f6d18d20ba18775f26a43898bae6

e37c045418259ecdc07874b85e7b688ba53f5a7dc989db19d7e8c440300bd574

75ea6e8dfaf56fb35f35cb043bd77aef9e2c7d46f3e2a0454dff0952a09c134f

a65e01412610e5ed8fde12cb78e6265a18ef78d2fd3c8c14ed8a3d1cef17c91d

7170b104367530ae837daed466035a8be719fdb17423fc01da9c0ded74ca6ad1

13acddf9b7c2daafd815cbfa75fbb778a7074a6f90277e858040275ae61a252b

625ed818a25c63d8b2c264d0f5bd96ba5ad1c702702d8ffaa4e0e93e5f411fac

a56cd758608034c90e81e4d4f1fe383982247d6aeffd74a1dd98d84e9b56afdf

a4b969b93f7882ed2d15fd10970c4720961e42f3ae3fced501c0a1ffa3896ff5

e833bbb79ca8ea1dbeb408520b97fb5a1b691d5a5f9c4f9deabecb3787b47f73

8e9136d6dc7419469c959241bc8745af7ba51c7b02a12d04fec0bc4d3f7dcdf0

### **CMSTAR.B Download Locations**

http://108.61.175\[.\]110/tlhXVFeBvT64LC9.dat  
http://104.238.188\[.\]211/gl7xljvn3fqGt3u.dat  
http://45.77.60\[.\]138/c2KoCT5OHcVwGi7.dat  
http://108.61.175\[.\]110/gkMmqVvZ7gGGxpY.dat  
http://108.61.175\[.\]110/z\_gaDZyeZXvScQ6.dat  
http://108.61.175\[.\]110/bDtzGVtqgiJU9PI.dat  
http://45.77.60\[.\]138/liW0ecpxEWCfIgU.dat  
http://45.77.60\[.\]138/JUmoT4Pbw6U2xcj.dat  
http://108.61.175\[.\]110/oiUfxZfej29MAbF.dat  
http://108.61.103\[.\]123/jvZfZ0gdTWtr46y.dat  
http://108.61.103\[.\]123/06JcD5jz5dSHVAy.dat  
http://108.61.103\[.\]123/nj3dsMMpyQQDBF3.dat  
http://108.61.103\[.\]123/fHZvWtBGlFvs2Nr.dat  
http://45.77.60\[.\]138/w57E8dktKb9UQyV.dat

### **CMSTAR.C SHA256**

85e06a2beaa4469f13ca58d5d09fec672d3d8962a7adad3c3cb74f3f9ef1fed4

b8ef93227b59e6c8d3a1494b4860d15be819fae17b57fd56bfff9a51b7972ff0

9e6fdbbc2371ac8bc6db3b878475ed0b0af8950d50a4652df688e778beb87397

4e38e627ae21f1a85aa963ca990a66cf75789b450605fdca2f31ee6f0f8ab8f2

f4ff0ca7f2ea2a011a2a4615d9b488b7806ff5dd61577a9e3a9860f2980e7fc0

8de3fa2614b1767cfd12936c5adf4423ef25ea60800fa170752266e0ca063274

38197abde967326568e101b65203c2efa75500e5f3c084b6dd08fd1ba1430726

726df91a395827d11dc433854b3f19b3e28eac4feff329e0bdad93890b03af84

5703565ec64d72eb693b9fafcba5951e937c8ee38829948e9518b7d226f81c10

d0544a3e6d1b34b8b4e976c7fc62d4500f28f617e2f549d9a3e590b71b1f9cc5

2a8e5551b9905e907da7268aba50fcbc526cfd0549ff2e352f9f4d1d71bf32a7

d7cd6f367a84f6d5cf5ffb3c2537dd3f48297bd45a8f5a4c50190f683b7c9e90

8f7294072a470b886791a7a32eedf0f0505aaecec154626c6334d986957086e4

6419255d017b217fe984d3439694eb96806d06c7ea41a422298650969028c08c

### **CMSTAR.C Download Locations**

http://45.77.58\[.\]49/54xfapkezW64xDE.dat  
http://45.77.58\[.\]49/54xfapkezW64xDE.dat  
http://45.77.62\[.\]181/naIXl13kqeV7Y2j.dat  
http://45.77.58\[.\]160/9EkCWYA3OtDbz1l.dat  
http://45.77.58\[.\]160/8h5NPYB5fAn301E.dat  
http://45.77.58\[.\]160/9EkCWYA3OtDbz1l.dat  
http://45.77.60\[.\]138/3kK24dXFYRgM6Ac.dat  
http://45.77.60\[.\]138/ezD19AweVIj5NaH.dat  
http://45.77.60\[.\]138/VFdSKlgCAZD7mmp.dat  
http://45.77.60\[.\]138/HJDBvnJ7wc4S5qZ.dat  
http://45.77.60\[.\]138/jVJlw3wp379neaJ.dat  
http://45.77.60\[.\]138/YXza9HkKWzqtXlt.dat  
http://45.77.60\[.\]138/UScHrzGWbXb01gv.dat  
http://45.77.60\[.\]138/WsEeRyHEhLO1kUm.dat
Back to top

### Tags

* [BYEBY](https://unit42.paloaltonetworks.com/tag/byeby/ "BYEBY")
* [Cmstar](https://unit42.paloaltonetworks.com/tag/cmstar/ "cmstar")
* [Phishing](https://unit42.paloaltonetworks.com/tag/phishing/ "phishing")
* [PYLOT](https://unit42.paloaltonetworks.com/tag/pylot/ "PYLOT")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Striking Oil: A Closer Look at Adversary Infrastructure](https://unit42.paloaltonetworks.com/unit42-striking-oil-closer-look-adversary-infrastructure/ "Striking Oil: A Closer Look at Adversary Infrastructure")

### Table of Contents

* 

### Related Articles

* [Russian Global Webmail Espionage](https://unit42.paloaltonetworks.com/russian-webmail-espionage/ "article - table of contents")
* [Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector](https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-domains/ "article - table of contents")
* [When "Hi, This Is IT" Comes Through Microsoft Teams](https://unit42.paloaltonetworks.com/microsoft-teams-phishing/ "article - table of contents")

## Related Malware Resources

![Pictorial representation of a magnifying glass illuminating a glowing orange circular digital circuit interface on a dark, high-tech background.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 16, 2026 [#### Atomic macOS (AMOS) Stealer Activity](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/)

* [MacOS](https://unit42.paloaltonetworks.com/tag/macos/ "macOS")

* [Threat intelligence](https://unit42.paloaltonetworks.com/tag/threat-intelligence/ "threat intelligence")

* [Unit 42](https://unit42.paloaltonetworks.com/tag/unit-42/ "Unit 42")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/ "Atomic macOS (AMOS) Stealer Activity")  
  ![Pictorial representation of post-exploitation identity misuse in SPIFFE/SPIRE. Close-up of a person wearing glasses, with computer code reflected in the lenses.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/12_Security-Technology_Category_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 10, 2026 [#### The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/)

* [API](https://unit42.paloaltonetworks.com/tag/api/ "API")

* [Cryptographic](https://unit42.paloaltonetworks.com/tag/cryptographic/ "cryptographic")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ "The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE")  
  ![Pictorial representation of a pay-per-install threat group campaign prodiving infection service for spreading malware. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip, symbolizing data processing and transfer. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/04_Malware_Category_1920x900-6-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 9, 2026 [#### Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/)

* [ARKTunnel](https://unit42.paloaltonetworks.com/tag/arktunnel/ "ARKTunnel")

* [C2](https://unit42.paloaltonetworks.com/tag/c2/ "C2")

* [CL-CRI-1171](https://unit42.paloaltonetworks.com/tag/cl-cri-1171/ "CL-CRI-1171")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/ "Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure")  
  ![Pictorial representation of attackers using AI tools to target Latin American organizations. A vibrant cityscape with silhouettes of numerous people walking along a bustling street. The scene is illuminated by bright urban lights and digital-like particles, creating a dynamic and futuristic atmosphere.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/AdobeStock_768915868-2-1-786x373.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) September 3, 2026 [#### Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [CL-CRI-1131](https://unit42.paloaltonetworks.com/tag/cl-cri-1131/ "CL-CRI-1131")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ "Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America")  
  ![Pictorial representation of vishing campaigns in Microsoft Teams. A digital image of a skull formed by blue binary code on a black background, with scattered ones and zeros and digital noise, symbolizes how stealthy prompt injection attacks can exploit AI logic to bypass security controls.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 31, 2026 [#### Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/)

* [Cloaked Ursa](https://unit42.paloaltonetworks.com/tag/cloaked-ursa/ "Cloaked Ursa")

* [Entra ID](https://unit42.paloaltonetworks.com/tag/entra-id/ "Entra ID")

* [Microsoft Teams](https://unit42.paloaltonetworks.com/tag/microsoft-teams/ "Microsoft Teams")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/ "Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams")  
  ![Pictorial representation of AI-enabled malware. A vibrant digital interface displaying various icons and graphs, resembling a futuristic network or data analysis dashboard. The scene is illuminated with glowing lights and patterns.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/AdobeStock_1270203474-2-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 25, 2026 [#### The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/)

* [Backdoor](https://unit42.paloaltonetworks.com/tag/backdoor/ "backdoor")

* [Bitcoin](https://unit42.paloaltonetworks.com/tag/bitcoin/ "Bitcoin")

* [DLL hijacking](https://unit42.paloaltonetworks.com/tag/dll-hijacking/ "DLL hijacking")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/ "The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution")  
  ![Pictorial representation of identity abuse through trusted communication channels. Close-up view of a digital screen displaying a glitched and pixelated image of a skull-like shape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/02_Malware_Category_1920x900-2-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 20, 2026 [#### Identity Abuse Through Trusted Communication Channels](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/)

* [Authentication](https://unit42.paloaltonetworks.com/tag/authentication/ "authentication")

* [Identity theft](https://unit42.paloaltonetworks.com/tag/identity-theft/ "identity theft")

* [Malware](https://unit42.paloaltonetworks.com/tag/malware/ "malware")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/communication-channel-identity-risks/ "Identity Abuse Through Trusted Communication Channels")  
  ![Pictorial representation of Kimwolf botnet malware family. Digital screen with a warning sign reading "Malware." The background features lines of computer code and graphics, creating a sense of cybersecurity threat.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/07_Malware_Category_1920x900-3-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 11, 2026 [#### Kimwolf v7: An Evolution of the Kimwolf Botnet](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/)

* [Android APK](https://unit42.paloaltonetworks.com/tag/android-apk/ "Android APK")

* [Ethereum](https://unit42.paloaltonetworks.com/tag/ethereum/ "Ethereum")

* [HTTP](https://unit42.paloaltonetworks.com/tag/http/ "HTTP")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/ "Kimwolf v7: An Evolution of the Kimwolf Botnet")  
  ![Pictorial representatiom pf Aeternum's blockchain C2. A close-up of a computer circuit board with a central microchip is depicted. Red digital data streams in the form of glowing binary numbers and arrows appear to flow in and out of the chip. The scene is illuminated with a futuristic blue and red glow.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/04_Malware_Category_1920x900-4-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) August 10, 2026 [#### The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/)

* [Aeternum](https://unit42.paloaltonetworks.com/tag/aeternum/ "Aeternum")

* [Infection chain](https://unit42.paloaltonetworks.com/tag/infection-chain/ "infection chain")

* [JSON](https://unit42.paloaltonetworks.com/tag/json/ "JSON")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications")  
  ![Pictorial representation of ChainDrop, a self-propagating npm worm. An artistic depiction of a digital workspace featuring an open laptop with a red virus on the screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/03_Malware_Category_1920x900-7-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) August 6, 2026 [#### ChainDrop: Inside a Self-Propagating npm Worm](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/)

* [Blockchain](https://unit42.paloaltonetworks.com/tag/blockchain/ "blockchain")

* [ChainDrop](https://unit42.paloaltonetworks.com/tag/chaindrop/ "ChainDrop")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/ "ChainDrop: Inside a Self-Propagating npm Worm")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
